Open5gs Security Vulnerabilities (CVEs)

Track 77 security vulnerabilities affecting Open5gs products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.

1 Critical
35 High
37 Medium
4 Low
🔔 Get Alerts for Open5gs
CVE-2026-2523 5.3

This vulnerability in Open5GS SMF component allows remote attackers to trigger a reachable assertion via manipulated PDP context requests, potentially...

Feb 16, 2026
CVE-2026-2522 5.3

A memory corruption vulnerability in Open5GS MME component allows remote attackers to potentially crash the service or execute arbitrary code. This af...

Feb 16, 2026
CVE-2026-2062 5.3

This CVE describes a null pointer dereference vulnerability in Open5GS PGW S5U Address Handler that can cause denial of service. Attackers can remotel...

Feb 6, 2026
CVE-2025-15555 7.3

A stack-based buffer overflow vulnerability in Open5GS allows remote attackers to execute arbitrary code or cause denial of service by manipulating th...

Feb 4, 2026
CVE-2026-1737 5.3

This vulnerability in Open5GS allows remote attackers to trigger a reachable assertion in the CreateBearerRequest handler, potentially causing denial ...

Feb 2, 2026
CVE-2026-1738 5.3

CVE-2026-1738 is a reachable assertion vulnerability in Open5GS SGWC component that allows remote attackers to cause denial of service by manipulating...

Feb 2, 2026
CVE-2026-1736 5.3

A reachable assertion vulnerability in Open5GS SGWC component allows remote attackers to cause denial of service by sending specially crafted requests...

Feb 2, 2026
CVE-2026-1586 5.3

A denial-of-service vulnerability exists in Open5GS SGWC component where remote attackers can manipulate the ogs_gtp2_f_teid_to_ip function to crash t...

Jan 29, 2026
CVE-2026-1587 5.3

A denial-of-service vulnerability exists in Open5GS SGWC component where the sgwc_s11_handle_modify_bearer_request function can be remotely triggered ...

Jan 29, 2026
CVE-2026-1521 5.3

A remote denial-of-service vulnerability exists in Open5GS SGWC component where manipulation of the sgwc_s5c_handle_bearer_resource_failure_indication...

Jan 28, 2026
CVE-2026-0622 6.5

Open5GS WebUI uses a hard-coded JWT signing key ('change-me') when the JWT_SECRET_KEY environment variable is not set, allowing attackers to forge aut...

Jan 20, 2026
CVE-2025-15539 5.3

A denial-of-service vulnerability exists in Open5GS SGWC component where remote attackers can crash the service by sending malicious S11 protocol mess...

Jan 19, 2026
CVE-2025-15532 5.3

CVE-2025-15532 is a resource consumption vulnerability in Open5GS's Timer Handler component that allows remote attackers to cause denial of service th...

Jan 17, 2026
CVE-2025-15531 5.3

This vulnerability in Open5GS allows remote attackers to trigger a reachable assertion in the sgwc_bearer_add function, potentially causing denial of ...

Jan 17, 2026
CVE-2025-15530 5.3

This vulnerability in Open5GS allows remote attackers to trigger a reachable assertion in the SGW-C component, potentially causing denial of service. ...

Jan 17, 2026
CVE-2025-15528 5.3

A denial-of-service vulnerability exists in Open5GS's GTPv2 Bearer Response Handler component. Attackers can remotely crash affected systems by sendin...

Jan 16, 2026
CVE-2025-15529 5.3

A denial-of-service vulnerability exists in Open5GS's SGWC component where remote attackers can manipulate the sgwc_s5c_handle_create_session_response...

Jan 16, 2026
CVE-2025-15418 3.3

A local denial-of-service vulnerability exists in Open5GS versions up to 2.7.6 where the ogs_gtp2_parse_bearer_qos function mishandles Bearer QoS IE L...

Jan 2, 2026
CVE-2025-15176 5.3

This vulnerability in Open5GS allows remote attackers to trigger a reachable assertion in the PFCP Session Establishment Request Handler by manipulati...

Dec 29, 2025
CVE-2025-14955 3.7

This vulnerability in Open5GS PFCP handler allows remote attackers to exploit improper initialization in the ogs_pfcp_handle_create_pdr function. It a...

Dec 19, 2025
CVE-2025-14954 3.7

This vulnerability in Open5GS allows remote attackers to trigger reachable assertions in PFCP (Packet Forwarding Control Protocol) handling functions,...

Dec 19, 2025
CVE-2025-14953 3.1

A null pointer dereference vulnerability in Open5GS's PFCP handler allows remote attackers to cause denial of service by crashing the service. This af...

Dec 19, 2025
CVE-2025-65559 7.5

A reachable assertion vulnerability in Open5GS UPF component causes denial of service when processing malformed PFCP Session Establishment Requests wi...

Dec 18, 2025
CVE-2025-63288 7.5

Open5GS AMF crashes when receiving a malformed NGSetupRequest message, causing denial of service for 5G core network users. This affects all deploymen...

Nov 10, 2025
CVE-2025-41067 7.5

A reachable assertion vulnerability in Open5GS NRF (Network Repository Function) allows attackers with network connectivity to send a specific SBI req...

Oct 27, 2025
CVE-2025-55904 4.0

Open5GS v2.7.5 is vulnerable to a NULL pointer dereference when receiving multipart/related HTTP POST requests with empty bodies to its Service-Based ...

Sep 17, 2025
CVE-2025-52322 7.5

A vulnerability in Open5GS allows remote attackers to cause denial of service by sending a specially crafted Create Session Request message to the SMF...

Sep 9, 2025
CVE-2025-52288 7.5

This vulnerability in Open5GS allows attackers to cause denial of service by triggering an assertion failure through repeated UE connect/disconnect me...

Sep 8, 2025
CVE-2025-9405 5.3

A reachable assertion vulnerability in Open5GS AMF component allows remote attackers to cause denial of service by triggering an assertion failure in ...

Aug 25, 2025
CVE-2025-8805 5.3

A denial-of-service vulnerability exists in Open5GS SMF component where the smf_gsm_state_wait_pfcp_deletion function can be manipulated remotely to c...

Aug 10, 2025
CVE-2025-8804 5.3

This vulnerability in Open5GS AMF component allows remote attackers to trigger a reachable assertion via the ngap_build_downlink_nas_transport functio...

Aug 10, 2025
CVE-2025-8803 5.3

This vulnerability in Open5GS AMF component allows remote attackers to cause denial of service by exploiting a flaw in the gmm_state_de_registered/gmm...

Aug 10, 2025
CVE-2025-8802 5.3

A denial-of-service vulnerability in Open5GS SMF component allows remote attackers to crash the service by manipulating stream arguments in the smf_st...

Aug 10, 2025
CVE-2025-8801 5.3

This vulnerability in Open5GS AMF component allows remote attackers to cause denial of service by exploiting a flaw in the gmm_state_exception functio...

Aug 10, 2025
CVE-2025-8800 5.3

A denial-of-service vulnerability exists in Open5GS AMF component where the esm_handle_pdn_connectivity_request function can be manipulated by remote ...

Aug 10, 2025
CVE-2025-29646 7.1

A vulnerability in open5gs upf component allows remote attackers to cause denial of service by sending specially crafted PFCP SessionEstablishmentRequ...

Jun 18, 2025
CVE-2025-44951 7.1

A buffer overflow vulnerability in the PFCP library of open5gs allows a local attacker to execute arbitrary code or cause denial of service by providi...

Jun 18, 2025
CVE-2025-5935 5.3

A denial-of-service vulnerability in Open5GS AMF/MME component allows remote attackers to crash the service by manipulating the ran_ue_id argument in ...

Jun 10, 2025
CVE-2025-5520 5.3

A reachable assertion vulnerability in Open5GS AMF/MME components allows remote attackers to cause denial of service by triggering assertion failures ...

Jun 3, 2025
CVE-2025-25774 6.5

This vulnerability in Open5GS allows attackers to cause a denial of service by triggering a crash in the AMF component during specific handover scenar...

Mar 12, 2025
CVE-2025-1893 4.3

A denial-of-service vulnerability in Open5GS AMF component allows a single malicious UE to crash the AMF service by exploiting the gmm_state_authentic...

Mar 4, 2025
CVE-2024-56921 7.5

This vulnerability in Open5gs AMF allows remote attackers to cause a denial of service by sending specially crafted InitialUEMessage or Registration r...

Feb 3, 2025
CVE-2024-57519 7.5

A denial-of-service vulnerability in Open5GS v2.7.2 allows remote attackers to crash the service via the ogs_dbi_auth_info function. This affects all ...

Jan 28, 2025
CVE-2024-24429 8.6

This vulnerability in Open5GS allows attackers to trigger a denial of service by sending a specially crafted NGAP packet to the nas_eps_send_emm_to_es...

Jan 22, 2025
CVE-2024-24430 7.5

This vulnerability in Open5GS allows attackers to trigger a reachable assertion in the mme_ue_find_by_imsi function by sending a specially crafted NAS...

Jan 22, 2025
CVE-2024-24432 5.3

This vulnerability in Open5GS allows attackers to trigger a reachable assertion in the ogs_kdf_hash_mme function by sending a specially crafted NAS pa...

Jan 22, 2025
CVE-2024-34235 8.6

CVE-2024-34235 is a remotely triggerable assertion vulnerability in Open5GS MME that allows denial of service attacks. Attackers can send malformed S1...

Jan 22, 2025
CVE-2023-37015 8.6

This vulnerability allows remote attackers to cause denial of service by sending malformed ASN.1 packets to Open5GS MME servers. Attackers can repeate...

Jan 22, 2025
CVE-2023-37016 8.6

CVE-2023-37016 is a remotely triggerable assertion vulnerability in Open5GS MME that allows denial of service attacks. Attackers can send malformed AS...

Jan 22, 2025
CVE-2023-37017 8.6

Open5GS MME versions up to 2.6.4 contain a remotely triggerable assertion via malformed ASN.1 packets on the S1AP interface. Attackers can send S1Setu...

Jan 22, 2025

Why Monitor Open5gs Security Vulnerabilities?

Real-time CVE tracking: Our automated system monitors 77+ known vulnerabilities affecting Open5gs products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.

Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Open5gs packages in under 60 seconds. No agents required - completely agentless scanning that works across Open5gs deployments.

Free vulnerability database: Access detailed information about every Open5gs CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.

🚀 Get Started in 60 Seconds

  • Register free account & add your servers
  • Run one-time scan or schedule automatic monitoring (every 1-24 hours)
  • Receive instant alerts when new Open5gs CVEs affect your systems
  • Access dashboard with severity breakdown & fix instructions
Start Monitoring Open5gs CVEs Free